Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-1724

Maximum Unchanged Password Days configuration is not respected by the Applications

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Low Low
    • 2.0.4
    • 2.0.1
    • None
    • None
    • Tested with JIRA 4.0

      Maximum Unchanged Password Days (Internal Directory) configuration is not respected by the Applications, only by the Crowd console.

      If the password is expired, Crowd still allow users to authenticate to the Applications.

            [CWD-1724] Maximum Unchanged Password Days configuration is not respected by the Applications

            This is not a minor bug, it is at least a critical bug. You allow users to log in with a password that is not valid any more! When our security-officer gets info about this he will request to shut down Crowd and replace it by an other software.
            When the JIRA-Stack is not able to handle "maximum unchanged days" crowd should not tell JIRA that the incredenials are valid.
            Fix this immediate please!

            Wolfgang Fellner added a comment - This is not a minor bug, it is at least a critical bug. You allow users to log in with a password that is not valid any more! When our security-officer gets info about this he will request to shut down Crowd and replace it by an other software. When the JIRA-Stack is not able to handle "maximum unchanged days" crowd should not tell JIRA that the incredenials are valid. Fix this immediate please!

            Hi Richard,

            It is strange. The reason is partly historic: JIRA has a completely different user management stack, and there's no way for Crowd to communicate concepts like "maximum unchanged days" to it.

            We're currently working to replace the JIRA stack with one derived from Crowd. This is a mammoth undertaking, but when we're done it'll allow us to fix issues like this.

            Cheers,
            Dave.
            Integration Product Manager.

            David O'Flynn [Atlassian] added a comment - Hi Richard, It is strange. The reason is partly historic: JIRA has a completely different user management stack, and there's no way for Crowd to communicate concepts like "maximum unchanged days" to it. We're currently working to replace the JIRA stack with one derived from Crowd. This is a mammoth undertaking, but when we're done it'll allow us to fix issues like this. Cheers, Dave. Integration Product Manager.

            Crowd is being sold as a single sign-on server - yet it does not work with Jira. In our case, we want to use Jira for tracking issues, but we require greater security than is offered by Jira out-of-the-box.
            Therefore we intend to use Crowd as a password policy manager for Jira.
            However, it does not appear to function correctly.
            It seems very strange that Crowd does not function correctly when used with another tool from the Atlassian offering.

            Regards
            Richard Campbell
            Sony Europe

            Richard Campbell added a comment - Crowd is being sold as a single sign-on server - yet it does not work with Jira. In our case, we want to use Jira for tracking issues, but we require greater security than is offered by Jira out-of-the-box. Therefore we intend to use Crowd as a password policy manager for Jira. However, it does not appear to function correctly. It seems very strange that Crowd does not function correctly when used with another tool from the Atlassian offering. Regards Richard Campbell Sony Europe

              pkuo Peggy
              rbattaglin Renan Battaglin
              Affected customers:
              3 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: